2 دقائق قراءة
هذا المحتوى متاح حاليًا باللغة الإنجليزية فقط.
A – D
| Term | Meaning |
|---|---|
| APT | Advanced persistent threat: a well-resourced actor that aims to stay undetected in a network for a long time. |
| Attack Surface Management (ASM) | Continuous discovery and risk tracking of every internet-facing asset. |
| BEC | Business email compromise: an attacker poses as an executive or supplier to request payments or data. |
| C2 | Command and control: infrastructure an attacker uses to remotely manage compromised systems. |
| CVE | Common Vulnerabilities and Exposures: the standard identifier for publicly disclosed vulnerabilities. |
| CVSS | Common Vulnerability Scoring System: a 0–10 score for a vulnerability’s technical severity. |
| DDoS | Distributed denial of service: overwhelming a service with traffic from many sources. |
| DMARC | An email authentication policy telling receivers how to handle spoofed mail from your domain. |
E – L
| Term | Meaning |
|---|---|
| EDR | Endpoint detection and response: software that detects and responds to suspicious activity on endpoints. |
| Exploit | Code or a technique that takes advantage of a vulnerability. |
| IDOR | Insecure direct object reference: an authorization flaw where changing an identifier exposes other users’ objects. |
| IOC | Indicator of compromise: a technical trace of an attack (IP, domain, file hash). |
| Kerberoasting | Requesting Kerberos tickets for service accounts and cracking their passwords offline. |
| Lateral movement | An attacker moving from one system to another inside a network. |
M – R
| Term | Meaning |
|---|---|
| MDR | Managed detection and response: monitoring and first response delivered as a service. |
| MFA | Multi-factor authentication: sign-in that requires more than a password. |
| MITRE ATT&CK | A public knowledge base classifying adversary tactics and techniques. |
| Phishing | Tricking users with fake messages into giving up information or taking harmful actions. |
| Prompt injection | Getting a language model to follow unintended instructions through its input or the content it reads. |
| Purple team | Red and blue teams working together to improve detection. |
| Ransomware | Malware that encrypts or steals data and demands a ransom. |
| Red team | A team or engagement that tests detection and response with realistic attack scenarios. |
S – Z
| Term | Meaning |
|---|---|
| SIEM | A platform that collects and correlates logs from many sources and raises alerts. |
| SOAR | A platform that automates and orchestrates security response steps. |
| SOC | Security operations center: the team that monitors and responds to events. |
| SQL injection | User input leaking into a database query, allowing data to be read or modified. |
| SSRF | Server-side request forgery: forcing a server to send requests to attacker-chosen addresses. |
| TTP | Tactics, techniques and procedures of a threat actor. |
| XDR | Extended detection and response across endpoint, network, email and cloud data. |
| Zero-day | A vulnerability with no vendor fix available yet. |
| Zero Trust | A security model that trusts no access by default and verifies every request. |